1 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
2 <html><head><title>LLVM Assembly Language Reference Manual</title></head>
5 <table width="100%" bgcolor="#330077" border=0 cellpadding=4 cellspacing=0>
6 <tr><td> <font size=+5 color="#EEEEFF" face="Georgia,Palatino,Times,Roman"><b>LLVM Language Reference Manual</b></font></td>
10 <li><a href="#abstract">Abstract</a>
11 <li><a href="#introduction">Introduction</a>
12 <li><a href="#identifiers">Identifiers</a>
13 <li><a href="#typesystem">Type System</a>
15 <li><a href="#t_primitive">Primitive Types</a>
17 <li><a href="#t_classifications">Type Classifications</a>
19 <li><a href="#t_derived">Derived Types</a>
21 <li><a href="#t_array" >Array Type</a>
22 <li><a href="#t_function">Function Type</a>
23 <li><a href="#t_pointer">Pointer Type</a>
24 <li><a href="#t_struct" >Structure Type</a>
25 <!-- <li><a href="#t_packed" >Packed Type</a> -->
28 <li><a href="#highlevel">High Level Structure</a>
30 <li><a href="#modulestructure">Module Structure</a>
31 <li><a href="#globalvars">Global Variables</a>
32 <li><a href="#functionstructure">Function Structure</a>
34 <li><a href="#instref">Instruction Reference</a>
36 <li><a href="#terminators">Terminator Instructions</a>
38 <li><a href="#i_ret" >'<tt>ret</tt>' Instruction</a>
39 <li><a href="#i_br" >'<tt>br</tt>' Instruction</a>
40 <li><a href="#i_switch">'<tt>switch</tt>' Instruction</a>
41 <li><a href="#i_invoke">'<tt>invoke</tt>' Instruction</a>
42 <li><a href="#i_unwind" >'<tt>unwind</tt>' Instruction</a>
44 <li><a href="#binaryops">Binary Operations</a>
46 <li><a href="#i_add" >'<tt>add</tt>' Instruction</a>
47 <li><a href="#i_sub" >'<tt>sub</tt>' Instruction</a>
48 <li><a href="#i_mul" >'<tt>mul</tt>' Instruction</a>
49 <li><a href="#i_div" >'<tt>div</tt>' Instruction</a>
50 <li><a href="#i_rem" >'<tt>rem</tt>' Instruction</a>
51 <li><a href="#i_setcc">'<tt>set<i>cc</i></tt>' Instructions</a>
53 <li><a href="#bitwiseops">Bitwise Binary Operations</a>
55 <li><a href="#i_and">'<tt>and</tt>' Instruction</a>
56 <li><a href="#i_or" >'<tt>or</tt>' Instruction</a>
57 <li><a href="#i_xor">'<tt>xor</tt>' Instruction</a>
58 <li><a href="#i_shl">'<tt>shl</tt>' Instruction</a>
59 <li><a href="#i_shr">'<tt>shr</tt>' Instruction</a>
61 <li><a href="#memoryops">Memory Access Operations</a>
63 <li><a href="#i_malloc" >'<tt>malloc</tt>' Instruction</a>
64 <li><a href="#i_free" >'<tt>free</tt>' Instruction</a>
65 <li><a href="#i_alloca" >'<tt>alloca</tt>' Instruction</a>
66 <li><a href="#i_load" >'<tt>load</tt>' Instruction</a>
67 <li><a href="#i_store" >'<tt>store</tt>' Instruction</a>
68 <li><a href="#i_getelementptr">'<tt>getelementptr</tt>' Instruction</a>
70 <li><a href="#otherops">Other Operations</a>
72 <li><a href="#i_phi" >'<tt>phi</tt>' Instruction</a>
73 <li><a href="#i_cast">'<tt>cast .. to</tt>' Instruction</a>
74 <li><a href="#i_call" >'<tt>call</tt>' Instruction</a>
75 <li><a href="#i_va_arg">'<tt>va_arg</tt>' Instruction</a>
78 <li><a href="#intrinsics">Intrinsic Functions</a>
80 <li><a href="#int_varargs">Variable Argument Handling Intrinsics</a>
82 <li><a href="#i_va_start">'<tt>llvm.va_start</tt>' Intrinsic</a>
83 <li><a href="#i_va_end" >'<tt>llvm.va_end</tt>' Intrinsic</a>
84 <li><a href="#i_va_copy" >'<tt>llvm.va_copy</tt>' Intrinsic</a>
88 <p><b>Written by <a href="mailto:sabre@nondot.org">Chris Lattner</a> and <A href="mailto:vadve@cs.uiuc.edu">Vikram Adve</a></b><p>
94 <!-- *********************************************************************** -->
95 <p><table width="100%" bgcolor="#330077" border=0 cellpadding=4 cellspacing=0>
96 <tr><td align=center><font color="#EEEEFF" size=+2 face="Georgia,Palatino"><b>
97 <a name="abstract">Abstract
98 </b></font></td></tr></table><ul>
99 <!-- *********************************************************************** -->
102 This document is a reference manual for the LLVM assembly language. LLVM is
103 an SSA based representation that provides type safety, low-level operations,
104 flexibility, and the capability of representing 'all' high-level languages
105 cleanly. It is the common code representation used throughout all phases of
106 the LLVM compilation strategy.
112 <!-- *********************************************************************** -->
113 </ul><table width="100%" bgcolor="#330077" border=0 cellpadding=4 cellspacing=0>
114 <tr><td align=center><font color="#EEEEFF" size=+2 face="Georgia,Palatino"><b>
115 <a name="introduction">Introduction
116 </b></font></td></tr></table><ul>
117 <!-- *********************************************************************** -->
119 The LLVM code representation is designed to be used in three different forms: as
120 an in-memory compiler IR, as an on-disk bytecode representation (suitable for
121 fast loading by a Just-In-Time compiler), and as a human readable assembly
122 language representation. This allows LLVM to provide a powerful intermediate
123 representation for efficient compiler transformations and analysis, while
124 providing a natural means to debug and visualize the transformations. The three
125 different forms of LLVM are all equivalent. This document describes the human
126 readable representation and notation.<p>
128 The LLVM representation aims to be a light-weight and low-level while being
129 expressive, typed, and extensible at the same time. It aims to be a "universal
130 IR" of sorts, by being at a low enough level that high-level ideas may be
131 cleanly mapped to it (similar to how microprocessors are "universal IR's",
132 allowing many source languages to be mapped to them). By providing type
133 information, LLVM can be used as the target of optimizations: for example,
134 through pointer analysis, it can be proven that a C automatic variable is never
135 accessed outside of the current function... allowing it to be promoted to a
136 simple SSA value instead of a memory location.<p>
138 <!-- _______________________________________________________________________ -->
139 </ul><a name="wellformed"><h4><hr size=0>Well Formedness</h4><ul>
141 It is important to note that this document describes 'well formed' LLVM assembly
142 language. There is a difference between what the parser accepts and what is
143 considered 'well formed'. For example, the following instruction is
144 syntactically okay, but not well formed:<p>
147 %x = <a href="#i_add">add</a> int 1, %x
150 ...because the definition of <tt>%x</tt> does not dominate all of its uses. The
151 LLVM infrastructure provides a verification pass that may be used to verify that
152 an LLVM module is well formed. This pass is automatically run by the parser
153 after parsing input assembly, and by the optimizer before it outputs bytecode.
154 The violations pointed out by the verifier pass indicate bugs in transformation
155 passes or input to the parser.<p>
157 <!-- Describe the typesetting conventions here. -->
160 <!-- *********************************************************************** -->
161 </ul><table width="100%" bgcolor="#330077" border=0 cellpadding=4 cellspacing=0>
162 <tr><td align=center><font color="#EEEEFF" size=+2 face="Georgia,Palatino"><b>
163 <a name="identifiers">Identifiers
164 </b></font></td></tr></table><ul>
165 <!-- *********************************************************************** -->
167 LLVM uses three different forms of identifiers, for different purposes:<p>
170 <li>Numeric constants are represented as you would expect: 12, -3 123.421, etc.
171 Floating point constants have an optional hexidecimal notation.
173 <li>Named values are represented as a string of characters with a '%' prefix.
174 For example, %foo, %DivisionByZero, %a.really.long.identifier. The actual
175 regular expression used is '<tt>%[a-zA-Z$._][a-zA-Z$._0-9]*</tt>'. Identifiers
176 which require other characters in their names can be surrounded with quotes. In
177 this way, anything except a <tt>"</tt> character can be used in a name.
179 <li>Unnamed values are represented as an unsigned numeric value with a '%'
180 prefix. For example, %12, %2, %44.
183 LLVM requires the values start with a '%' sign for two reasons: Compilers don't
184 need to worry about name clashes with reserved words, and the set of reserved
185 words may be expanded in the future without penalty. Additionally, unnamed
186 identifiers allow a compiler to quickly come up with a temporary variable
187 without having to avoid symbol table conflicts.<p>
189 Reserved words in LLVM are very similar to reserved words in other languages.
190 There are keywords for different opcodes ('<tt><a href="#i_add">add</a></tt>',
191 '<tt><a href="#i_cast">cast</a></tt>', '<tt><a href="#i_ret">ret</a></tt>',
192 etc...), for primitive type names ('<tt><a href="#t_void">void</a></tt>',
193 '<tt><a href="#t_uint">uint</a></tt>', etc...), and others. These reserved
194 words cannot conflict with variable names, because none of them start with a '%'
197 Here is an example of LLVM code to multiply the integer variable '<tt>%X</tt>'
202 %result = <a href="#i_mul">mul</a> uint %X, 8
205 After strength reduction:
207 %result = <a href="#i_shl">shl</a> uint %X, ubyte 3
212 <a href="#i_add">add</a> uint %X, %X <i>; yields {uint}:%0</i>
213 <a href="#i_add">add</a> uint %0, %0 <i>; yields {uint}:%1</i>
214 %result = <a href="#i_add">add</a> uint %1, %1
217 This last way of multiplying <tt>%X</tt> by 8 illustrates several important lexical features of LLVM:<p>
220 <li>Comments are delimited with a '<tt>;</tt>' and go until the end of line.
221 <li>Unnamed temporaries are created when the result of a computation is not
222 assigned to a named value.
223 <li>Unnamed temporaries are numbered sequentially
226 ...and it also show a convention that we follow in this document. When
227 demonstrating instructions, we will follow an instruction with a comment that
228 defines the type and name of value produced. Comments are shown in italic
231 The one non-intuitive notation for constants is the optional hexidecimal form of
232 floating point constants. For example, the form '<tt>double
233 0x432ff973cafa8000</tt>' is equivalent to (but harder to read than) '<tt>double
234 4.5e+15</tt>' which is also supported by the parser. The only time hexadecimal
235 floating point constants are useful (and the only time that they are generated
236 by the disassembler) is when an FP constant has to be emitted that is not
237 representable as a decimal floating point number exactly. For example, NaN's,
238 infinities, and other special cases are represented in their IEEE hexadecimal
239 format so that assembly and disassembly do not cause any bits to change in the
243 <!-- *********************************************************************** -->
244 </ul><table width="100%" bgcolor="#330077" border=0 cellpadding=4 cellspacing=0>
245 <tr><td align=center><font color="#EEEEFF" size=+2 face="Georgia,Palatino"><b>
246 <a name="typesystem">Type System
247 </b></font></td></tr></table><ul>
248 <!-- *********************************************************************** -->
250 The LLVM type system is one of the most important features of the intermediate
251 representation. Being typed enables a number of optimizations to be performed
252 on the IR directly, without having to do extra analyses on the side before the
253 transformation. A strong type system makes it easier to read the generated code
254 and enables novel analyses and transformations that are not feasible to perform
255 on normal three address code representations.<p>
257 <!-- The written form for the type system was heavily influenced by the
258 syntactic problems with types in the C language<sup><a
259 href="#rw_stroustrup">1</a></sup>.<p> -->
263 <!-- ======================================================================= -->
264 </ul><table width="100%" bgcolor="#441188" border=0 cellpadding=4 cellspacing=0>
265 <tr><td> </td><td width="100%"> <font color="#EEEEFF" face="Georgia,Palatino"><b>
266 <a name="t_primitive">Primitive Types
267 </b></font></td></tr></table><ul>
269 The primitive types are the fundemental building blocks of the LLVM system. The
270 current set of primitive types are as follows:<p>
272 <table border=0 align=center><tr><td>
274 <table border=1 cellspacing=0 cellpadding=4 align=center>
275 <tr><td><tt>void</tt></td> <td>No value</td></tr>
276 <tr><td><tt>ubyte</tt></td> <td>Unsigned 8 bit value</td></tr>
277 <tr><td><tt>ushort</tt></td><td>Unsigned 16 bit value</td></tr>
278 <tr><td><tt>uint</tt></td> <td>Unsigned 32 bit value</td></tr>
279 <tr><td><tt>ulong</tt></td> <td>Unsigned 64 bit value</td></tr>
280 <tr><td><tt>float</tt></td> <td>32 bit floating point value</td></tr>
281 <tr><td><tt>label</tt></td> <td>Branch destination</td></tr>
286 <table border=1 cellspacing=0 cellpadding=4 align=center>
287 <tr><td><tt>bool</tt></td> <td>True or False value</td></tr>
288 <tr><td><tt>sbyte</tt></td> <td>Signed 8 bit value</td></tr>
289 <tr><td><tt>short</tt></td> <td>Signed 16 bit value</td></tr>
290 <tr><td><tt>int</tt></td> <td>Signed 32 bit value</td></tr>
291 <tr><td><tt>long</tt></td> <td>Signed 64 bit value</td></tr>
292 <tr><td><tt>double</tt></td><td>64 bit floating point value</td></tr>
295 </td></tr></table><p>
299 <!-- _______________________________________________________________________ -->
300 </ul><a name="t_classifications"><h4><hr size=0>Type Classifications</h4><ul>
302 These different primitive types fall into a few useful classifications:<p>
304 <table border=1 cellspacing=0 cellpadding=4 align=center>
305 <tr><td><a name="t_signed">signed</td> <td><tt>sbyte, short, int, long, float, double</tt></td></tr>
306 <tr><td><a name="t_unsigned">unsigned</td><td><tt>ubyte, ushort, uint, ulong</tt></td></tr>
307 <tr><td><a name="t_integer">integer</td><td><tt>ubyte, sbyte, ushort, short, uint, int, ulong, long</tt></td></tr>
308 <tr><td><a name="t_integral">integral</td><td><tt>bool, ubyte, sbyte, ushort, short, uint, int, ulong, long</tt></td></tr>
309 <tr><td><a name="t_floating">floating point</td><td><tt>float, double</tt></td></tr>
310 <tr><td><a name="t_firstclass">first class</td><td><tt>bool, ubyte, sbyte, ushort, short,<br> uint, int, ulong, long, float, double, <a href="#t_pointer">pointer</a></tt></td></tr>
317 <!-- ======================================================================= -->
318 </ul><table width="100%" bgcolor="#441188" border=0 cellpadding=4 cellspacing=0><tr><td> </td><td width="100%"> <font color="#EEEEFF" face="Georgia,Palatino"><b>
319 <a name="t_derived">Derived Types
320 </b></font></td></tr></table><ul>
322 The real power in LLVM comes from the derived types in the system. This is what
323 allows a programmer to represent arrays, functions, pointers, and other useful
324 types. Note that these derived types may be recursive: For example, it is
325 possible to have a two dimensional array.<p>
329 <!-- _______________________________________________________________________ -->
330 </ul><a name="t_array"><h4><hr size=0>Array Type</h4><ul>
334 The array type is a very simple derived type that arranges elements sequentially
335 in memory. The array type requires a size (number of elements) and an
336 underlying data type.<p>
340 [<# elements> x <elementtype>]
343 The number of elements is a constant integer value, elementtype may be any type
348 <tt>[40 x int ]</tt>: Array of 40 integer values.<br>
349 <tt>[41 x int ]</tt>: Array of 41 integer values.<br>
350 <tt>[40 x uint]</tt>: Array of 40 unsigned integer values.<p>
353 Here are some examples of multidimensional arrays:<p>
355 <table border=0 cellpadding=0 cellspacing=0>
356 <tr><td><tt>[3 x [4 x int]]</tt></td><td>: 3x4 array integer values.</td></tr>
357 <tr><td><tt>[12 x [10 x float]]</tt></td><td>: 12x10 array of single precision floating point values.</td></tr>
358 <tr><td><tt>[2 x [3 x [4 x uint]]]</tt></td><td>: 2x3x4 array of unsigned integer values.</td></tr>
363 <!-- _______________________________________________________________________ -->
364 </ul><a name="t_function"><h4><hr size=0>Function Type</h4><ul>
368 The function type can be thought of as a function signature. It consists of a
369 return type and a list of formal parameter types. Function types are usually
370 used when to build virtual function tables (which are structures of pointers to
371 functions), for indirect function calls, and when defining a function.<p>
375 <returntype> (<parameter list>)
378 Where '<tt><parameter list></tt>' is a comma-separated list of type
379 specifiers. Optionally, the parameter list may include a type <tt>...</tt>,
380 which indicates that the function takes a variable number of arguments.
381 Variable argument functions can access their arguments with the <a
382 href="#int_varargs">variable argument handling intrinsic</a> functions.
387 <table border=0 cellpadding=0 cellspacing=0>
389 <tr><td><tt>int (int)</tt></td><td>: function taking an <tt>int</tt>, returning
390 an <tt>int</tt></td></tr>
392 <tr><td><tt>float (int, int *) *</tt></td><td>: <a href="#t_pointer">Pointer</a>
393 to a function that takes an <tt>int</tt> and a <a href="#t_pointer">pointer</a>
394 to <tt>int</tt>, returning <tt>float</tt>.</td></tr>
396 <tr><td><tt>int (sbyte *, ...)</tt></td><td>: A vararg function that takes at
397 least one <a href="#t_pointer">pointer</a> to <tt>sbyte</tt> (signed char in C),
398 which returns an integer. This is the signature for <tt>printf</tt> in
406 <!-- _______________________________________________________________________ -->
407 </ul><a name="t_struct"><h4><hr size=0>Structure Type</h4><ul>
411 The structure type is used to represent a collection of data members together in
412 memory. The packing of the field types is defined to match the ABI of the
413 underlying processor. The elements of a structure may be any type that has a
416 Structures are accessed using '<tt><a href="#i_load">load</a></tt> and '<tt><a
417 href="#i_store">store</a></tt>' by getting a pointer to a field with the '<tt><a
418 href="#i_getelementptr">getelementptr</a></tt>' instruction.<p>
422 { <type list> }
427 <table border=0 cellpadding=0 cellspacing=0>
429 <tr><td><tt>{ int, int, int }</tt></td><td>: a triple of three <tt>int</tt>
432 <tr><td><tt>{ float, int (int) * }</tt></td><td>: A pair, where the first
433 element is a <tt>float</tt> and the second element is a <a
434 href="#t_pointer">pointer</a> to a <a href="t_function">function</a> that takes
435 an <tt>int</tt>, returning an <tt>int</tt>.</td></tr>
440 <!-- _______________________________________________________________________ -->
441 </ul><a name="t_pointer"><h4><hr size=0>Pointer Type</h4><ul>
445 As in many languages, the pointer type represents a pointer or reference to
446 another object, which must live in memory.<p>
455 <table border=0 cellpadding=0 cellspacing=0>
457 <tr><td><tt>[4x int]*</tt></td><td>: <a href="#t_pointer">pointer</a> to <a
458 href="#t_array">array</a> of four <tt>int</tt> values</td></tr>
460 <tr><td><tt>int (int *) *</tt></td><td>: A <a href="#t_pointer">pointer</a> to a
461 <a href="t_function">function</a> that takes an <tt>int</tt>, returning an
462 <tt>int</tt>.</td></tr>
468 <!-- _______________________________________________________________________ -->
470 </ul><a name="t_packed"><h4><hr size=0>Packed Type</h4><ul>
472 Mention/decide that packed types work with saturation or not. Maybe have a packed+saturated type in addition to just a packed type.<p>
474 Packed types should be 'nonsaturated' because standard data types are not saturated. Maybe have a saturated packed type?<p>
479 <!-- *********************************************************************** -->
480 </ul><table width="100%" bgcolor="#330077" border=0 cellpadding=4 cellspacing=0>
481 <tr><td align=center><font color="#EEEEFF" size=+2 face="Georgia,Palatino"><b>
482 <a name="highlevel">High Level Structure
483 </b></font></td></tr></table><ul>
484 <!-- *********************************************************************** -->
487 <!-- ======================================================================= -->
488 </ul><table width="100%" bgcolor="#441188" border=0 cellpadding=4 cellspacing=0>
489 <tr><td> </td><td width="100%"> <font color="#EEEEFF" face="Georgia,Palatino"><b>
490 <a name="modulestructure">Module Structure
491 </b></font></td></tr></table><ul>
493 LLVM programs are composed of "Module"s, each of which is a translation unit of
494 the input programs. Each module consists of functions, global variables, and
495 symbol table entries. Modules may be combined together with the LLVM linker,
496 which merges function (and global variable) definitions, resolves forward
497 declarations, and merges symbol table entries. Here is an example of the "hello world" module:<p>
500 <i>; Declare the string constant as a global constant...</i>
501 <a href="#identifiers">%.LC0</a> = <a href="#linkage_internal">internal</a> <a href="#globalvars">constant</a> <a href="#t_array">[13 x sbyte]</a> c"hello world\0A\00" <i>; [13 x sbyte]*</i>
503 <i>; External declaration of the puts function</i>
504 <a href="#functionstructure">declare</a> int %puts(sbyte*) <i>; int(sbyte*)* </i>
506 <i>; Definition of main function</i>
507 int %main() { <i>; int()* </i>
508 <i>; Convert [13x sbyte]* to sbyte *...</i>
509 %cast210 = <a href="#i_getelementptr">getelementptr</a> [13 x sbyte]* %.LC0, long 0, long 0 <i>; sbyte*</i>
511 <i>; Call puts function to write out the string to stdout...</i>
512 <a href="#i_call">call</a> int %puts(sbyte* %cast210) <i>; int</i>
513 <a href="#i_ret">ret</a> int 0
517 This example is made up of a <a href="#globalvars">global variable</a> named
518 "<tt>.LC0</tt>", an external declaration of the "<tt>puts</tt>" function, and a
519 <a href="#functionstructure">function definition</a> for "<tt>main</tt>".<p>
522 In general, a module is made up of a list of global values, where both functions
523 and global variables are global values. Global values are represented by a
524 pointer to a memory location (in this case, a pointer to an array of char, and a
525 pointer to a function), and have one of the following linkage types:<p>
528 <a name="linkage_internal">
529 <dt><tt><b>internal</b></tt>
531 <dd>Global values with internal linkage are only directly accessible by objects
532 in the current module. In particular, linking code into a module with an
533 internal global value may cause the internal to be renamed as necessary to avoid
534 collisions. Because the symbol is internal to the module, all references can be
535 updated. This corresponds to the notion of the '<tt>static</tt>' keyword in C,
536 or the idea of "anonymous namespaces" in C++.<p>
538 <a name="linkage_linkonce">
539 <dt><tt><b>linkonce</b></tt>:
541 <dd>"<tt>linkonce</tt>" linkage is similar to <tt>internal</tt> linkage, with
542 the twist that linking together two modules defining the same <tt>linkonce</tt>
543 globals will cause one of the globals to be discarded. This is typically used
544 to implement inline functions.<p>
546 <a name="linkage_appending">
547 <dt><tt><b>appending</b></tt>:
549 <dd>"<tt>appending</tt>" linkage may only applied to global variables of pointer
550 to array type. When two global variables with appending linkage are linked
551 together, the two global arrays are appended together. This is the LLVM,
552 typesafe, equivalent of having the system linker append together "sections" with
553 identical names when .o files are linked.<p>
555 <a name="linkage_external">
556 <dt><tt><b>externally visible</b></tt>:
558 <dd>If none of the above identifiers are used, the global is externally visible,
559 meaning that it participates in linkage and can be used to resolve external
560 symbol references.<p>
565 For example, since the "<tt>.LC0</tt>" variable is defined to be internal, if
566 another module defined a "<tt>.LC0</tt>" variable and was linked with this one,
567 one of the two would be renamed, preventing a collision. Since "<tt>main</tt>"
568 and "<tt>puts</tt>" are external (i.e., lacking any linkage declarations), they
569 are accessible outside of the current module. It is illegal for a function
570 <i>declaration</i> to have any linkage type other than "externally visible".<p>
573 <!-- ======================================================================= -->
574 </ul><table width="100%" bgcolor="#441188" border=0 cellpadding=4 cellspacing=0>
575 <tr><td> </td><td width="100%"> <font color="#EEEEFF" face="Georgia,Palatino"><b>
576 <a name="globalvars">Global Variables
577 </b></font></td></tr></table><ul>
579 Global variables define regions of memory allocated at compilation time instead
580 of run-time. Global variables may optionally be initialized. A variable may
581 be defined as a global "constant", which indicates that the contents of the
582 variable will never be modified (opening options for optimization). Constants
583 must always have an initial value.<p>
585 As SSA values, global variables define pointer values that are in scope
586 (i.e. they dominate) for all basic blocks in the program. Global variables
587 always define a pointer to their "content" type because they describe a region
588 of memory, and all memory objects in LLVM are accessed through pointers.<p>
592 <!-- ======================================================================= -->
593 </ul><table width="100%" bgcolor="#441188" border=0 cellpadding=4 cellspacing=0>
594 <tr><td> </td><td width="100%"> <font color="#EEEEFF" face="Georgia,Palatino"><b>
595 <a name="functionstructure">Functions
596 </b></font></td></tr></table><ul>
598 LLVM functions definitions are composed of a (possibly empty) argument list, an
599 opening curly brace, a list of basic blocks, and a closing curly brace. LLVM
600 function declarations are defined with the "<tt>declare</tt>" keyword, a
601 function name and a function signature.<p>
603 A function definition contains a list of basic blocks, forming the CFG for the
604 function. Each basic block may optionally start with a label (giving the basic
605 block a symbol table entry), contains a list of instructions, and ends with a <a
606 href="#terminators">terminator</a> instruction (such as a branch or function
609 The first basic block in program is special in two ways: it is immediately
610 executed on entrance to the function, and it is not allowed to have predecessor
611 basic blocks (i.e. there can not be any branches to the entry block of a
612 function). Because the block can have no predecessors, it also cannot have any
613 <a href="#i_phi">PHI nodes</a>.<p>
616 <!-- *********************************************************************** -->
617 </ul><table width="100%" bgcolor="#330077" border=0 cellpadding=4 cellspacing=0>
618 <tr><td align=center><font color="#EEEEFF" size=+2 face="Georgia,Palatino"><b>
619 <a name="instref">Instruction Reference
620 </b></font></td></tr></table><ul>
621 <!-- *********************************************************************** -->
623 The LLVM instruction set consists of several different classifications of
624 instructions: <a href="#terminators">terminator instructions</a>, <a
625 href="#binaryops">binary instructions</a>, <a href="#memoryops">memory
626 instructions</a>, and <a href="#otherops">other instructions</a>.<p>
629 <!-- ======================================================================= -->
630 </ul><table width="100%" bgcolor="#441188" border=0 cellpadding=4 cellspacing=0>
631 <tr><td> </td><td width="100%"> <font color="#EEEEFF" face="Georgia,Palatino"><b>
632 <a name="terminators">Terminator Instructions
633 </b></font></td></tr></table><ul>
635 As mentioned <a href="#functionstructure">previously</a>, every basic block in a
636 program ends with a "Terminator" instruction, which indicates which block should
637 be executed after the current block is finished. These terminator instructions
638 typically yield a '<tt>void</tt>' value: they produce control flow, not values
639 (the one exception being the '<a href="#i_invoke"><tt>invoke</tt></a>'
642 There are five different terminator instructions: the '<a
643 href="#i_ret"><tt>ret</tt></a>' instruction, the '<a
644 href="#i_br"><tt>br</tt></a>' instruction, the '<a
645 href="#i_switch"><tt>switch</tt></a>' instruction, the '<a
646 href="#i_invoke"><tt>invoke</tt></a>' instruction, and the '<a
647 href="#i_unwind"><tt>unwind</tt></a>' instruction.<p>
650 <!-- _______________________________________________________________________ -->
651 </ul><a name="i_ret"><h4><hr size=0>'<tt>ret</tt>' Instruction</h4><ul>
655 ret <type> <value> <i>; Return a value from a non-void function</i>
656 ret void <i>; Return from void function</i>
661 The '<tt>ret</tt>' instruction is used to return control flow (and a value) from
662 a function, back to the caller.<p>
664 There are two forms of the '<tt>ret</tt>' instructruction: one that returns a
665 value and then causes control flow, and one that just causes control flow to
670 The '<tt>ret</tt>' instruction may return any '<a href="#t_firstclass">first
671 class</a>' type. Notice that a function is not <a href="#wellformed">well
672 formed</a> if there exists a '<tt>ret</tt>' instruction inside of the function
673 that returns a value that does not match the return type of the function.<p>
677 When the '<tt>ret</tt>' instruction is executed, control flow returns back to
678 the calling function's context. If the caller is a "<a
679 href="#i_call"><tt>call</tt></a> instruction, execution continues at the
680 instruction after the call. If the caller was an "<a
681 href="#i_invoke"><tt>invoke</tt></a>" instruction, execution continues at the
682 beginning "normal" of the destination block. If the instruction returns a
683 value, that value shall set the call or invoke instruction's return value.<p>
688 ret int 5 <i>; Return an integer value of 5</i>
689 ret void <i>; Return from a void function</i>
693 <!-- _______________________________________________________________________ -->
694 </ul><a name="i_br"><h4><hr size=0>'<tt>br</tt>' Instruction</h4><ul>
698 br bool <cond>, label <iftrue>, label <iffalse>
699 br label <dest> <i>; Unconditional branch</i>
704 The '<tt>br</tt>' instruction is used to cause control flow to transfer to a
705 different basic block in the current function. There are two forms of this
706 instruction, corresponding to a conditional branch and an unconditional
711 The conditional branch form of the '<tt>br</tt>' instruction takes a single
712 '<tt>bool</tt>' value and two '<tt>label</tt>' values. The unconditional form
713 of the '<tt>br</tt>' instruction takes a single '<tt>label</tt>' value as a
718 Upon execution of a conditional '<tt>br</tt>' instruction, the '<tt>bool</tt>'
719 argument is evaluated. If the value is <tt>true</tt>, control flows to the
720 '<tt>iftrue</tt>' <tt>label</tt> argument. If "cond" is <tt>false</tt>,
721 control flows to the '<tt>iffalse</tt>' <tt>label</tt> argument.<p>
726 %cond = <a href="#i_setcc">seteq</a> int %a, %b
727 br bool %cond, label %IfEqual, label %IfUnequal
729 <a href="#i_ret">ret</a> int 1
731 <a href="#i_ret">ret</a> int 0
735 <!-- _______________________________________________________________________ -->
736 </ul><a name="i_switch"><h4><hr size=0>'<tt>switch</tt>' Instruction</h4><ul>
740 switch uint <value>, label <defaultdest> [ int <val>, label &dest>, ... ]
746 The '<tt>switch</tt>' instruction is used to transfer control flow to one of
747 several different places. It is a generalization of the '<tt>br</tt>'
748 instruction, allowing a branch to occur to one of many possible destinations.<p>
752 The '<tt>switch</tt>' instruction uses three parameters: a '<tt>uint</tt>'
753 comparison value '<tt>value</tt>', a default '<tt>label</tt>' destination, and
754 an array of pairs of comparison value constants and '<tt>label</tt>'s.<p>
758 The <tt>switch</tt> instruction specifies a table of values and destinations.
759 When the '<tt>switch</tt>' instruction is executed, this table is searched for
760 the given value. If the value is found, the corresponding destination is
761 branched to, otherwise the default value it transfered to.<p>
763 <h5>Implementation:</h5>
765 Depending on properties of the target machine and the particular <tt>switch</tt>
766 instruction, this instruction may be code generated as a series of chained
767 conditional branches, or with a lookup table.<p>
771 <i>; Emulate a conditional br instruction</i>
772 %Val = <a href="#i_cast">cast</a> bool %value to uint
773 switch uint %Val, label %truedest [int 0, label %falsedest ]
775 <i>; Emulate an unconditional br instruction</i>
776 switch uint 0, label %dest [ ]
778 <i>; Implement a jump table:</i>
779 switch uint %val, label %otherwise [ int 0, label %onzero,
781 int 2, label %ontwo ]
786 <!-- _______________________________________________________________________ -->
787 </ul><a name="i_invoke"><h4><hr size=0>'<tt>invoke</tt>' Instruction</h4><ul>
791 <result> = invoke <ptr to function ty> %<function ptr val>(<function args>)
792 to label <normal label> except label <exception label>
797 The '<tt>invoke</tt>' instruction causes control to transfer to a specified
798 function, with the possibility of control flow transfer to either the
799 '<tt>normal</tt>' <tt>label</tt> label or the '<tt>exception</tt>'
800 <tt>label</tt>. If the callee function returns with the "<tt><a
801 href="#i_ret">ret</a></tt>" instruction, control flow will return to the
802 "normal" label. If the callee (or any indirect callees) returns with the "<a
803 href="#i_unwind"><tt>unwind</tt></a>" instruction, control is interrupted, and
804 continued at the dynamically nearest "except" label.<p>
809 This instruction requires several arguments:<p>
812 <li>'<tt>ptr to function ty</tt>': shall be the signature of the pointer to
813 function value being invoked. In most cases, this is a direct function
814 invocation, but indirect <tt>invoke</tt>s are just as possible, branching off
815 an arbitrary pointer to function value.
817 <li>'<tt>function ptr val</tt>': An LLVM value containing a pointer to a
818 function to be invoked.
820 <li>'<tt>function args</tt>': argument list whose types match the function
821 signature argument types. If the function signature indicates the function
822 accepts a variable number of arguments, the extra arguments can be specified.
824 <li>'<tt>normal label</tt>': the label reached when the called function executes
825 a '<tt><a href="#i_ret">ret</a></tt>' instruction.
827 <li>'<tt>exception label</tt>': the label reached when a callee returns with the
828 <a href="#i_unwind"><tt>unwind</tt></a> instruction.
833 This instruction is designed to operate as a standard '<tt><a
834 href="#i_call">call</a></tt>' instruction in most regards. The primary
835 difference is that it establishes an association with a label, which is used by the runtime library to unwind the stack.<p>
837 This instruction is used in languages with destructors to ensure that proper
838 cleanup is performed in the case of either a <tt>longjmp</tt> or a thrown
839 exception. Additionally, this is important for implementation of
840 '<tt>catch</tt>' clauses in high-level languages that support them.<p>
844 %retval = invoke int %Test(int 15)
846 except label %TestCleanup <i>; {int}:retval set</i>
849 <!-- _______________________________________________________________________ -->
850 </ul><a name="i_unwind"><h4><hr size=0>'<tt>unwind</tt>' Instruction</h4><ul>
859 The '<tt>unwind</tt>' instruction unwinds the stack, continuing control flow at
860 the first callee in the dynamic call stack which used an <a
861 href="#i_invoke"><tt>invoke</tt></a> instruction to perform the call. This is
862 primarily used to implement exception handling.
866 The '<tt>unwind</tt>' intrinsic causes execution of the current function to
867 immediately halt. The dynamic call stack is then searched for the first <a
868 href="#i_invoke"><tt>invoke</tt></a> instruction on the call stack. Once found,
869 execution continues at the "exceptional" destination block specified by the
870 <tt>invoke</tt> instruction. If there is no <tt>invoke</tt> instruction in the
871 dynamic call chain, undefined behavior results.
875 <!-- ======================================================================= -->
876 </ul><table width="100%" bgcolor="#441188" border=0 cellpadding=4 cellspacing=0><tr><td> </td><td width="100%"> <font color="#EEEEFF" face="Georgia,Palatino"><b>
877 <a name="binaryops">Binary Operations
878 </b></font></td></tr></table><ul>
880 Binary operators are used to do most of the computation in a program. They
881 require two operands, execute an operation on them, and produce a single value.
882 The result value of a binary operator is not necessarily the same type as its
885 There are several different binary operators:<p>
888 <!-- _______________________________________________________________________ -->
889 </ul><a name="i_add"><h4><hr size=0>'<tt>add</tt>' Instruction</h4><ul>
893 <result> = add <ty> <var1>, <var2> <i>; yields {ty}:result</i>
897 The '<tt>add</tt>' instruction returns the sum of its two operands.<p>
900 The two arguments to the '<tt>add</tt>' instruction must be either <a href="#t_integer">integer</a> or <a href="#t_floating">floating point</a> values. Both arguments must have identical types.<p>
904 The value produced is the integer or floating point sum of the two operands.<p>
908 <result> = add int 4, %var <i>; yields {int}:result = 4 + %var</i>
912 <!-- _______________________________________________________________________ -->
913 </ul><a name="i_sub"><h4><hr size=0>'<tt>sub</tt>' Instruction</h4><ul>
917 <result> = sub <ty> <var1>, <var2> <i>; yields {ty}:result</i>
922 The '<tt>sub</tt>' instruction returns the difference of its two operands.<p>
924 Note that the '<tt>sub</tt>' instruction is used to represent the '<tt>neg</tt>'
925 instruction present in most other intermediate representations.<p>
929 The two arguments to the '<tt>sub</tt>' instruction must be either <a
930 href="#t_integer">integer</a> or <a href="#t_floating">floating point</a>
931 values. Both arguments must have identical types.<p>
935 The value produced is the integer or floating point difference of the two
940 <result> = sub int 4, %var <i>; yields {int}:result = 4 - %var</i>
941 <result> = sub int 0, %val <i>; yields {int}:result = -%var</i>
944 <!-- _______________________________________________________________________ -->
945 </ul><a name="i_mul"><h4><hr size=0>'<tt>mul</tt>' Instruction</h4><ul>
949 <result> = mul <ty> <var1>, <var2> <i>; yields {ty}:result</i>
953 The '<tt>mul</tt>' instruction returns the product of its two operands.<p>
956 The two arguments to the '<tt>mul</tt>' instruction must be either <a href="#t_integer">integer</a> or <a href="#t_floating">floating point</a> values. Both arguments must have identical types.<p>
960 The value produced is the integer or floating point product of the two
963 There is no signed vs unsigned multiplication. The appropriate action is taken
964 based on the type of the operand. <p>
969 <result> = mul int 4, %var <i>; yields {int}:result = 4 * %var</i>
973 <!-- _______________________________________________________________________ -->
974 </ul><a name="i_div"><h4><hr size=0>'<tt>div</tt>' Instruction</h4><ul>
978 <result> = div <ty> <var1>, <var2> <i>; yields {ty}:result</i>
983 The '<tt>div</tt>' instruction returns the quotient of its two operands.<p>
987 The two arguments to the '<tt>div</tt>' instruction must be either <a
988 href="#t_integer">integer</a> or <a href="#t_floating">floating point</a>
989 values. Both arguments must have identical types.<p>
993 The value produced is the integer or floating point quotient of the two
998 <result> = div int 4, %var <i>; yields {int}:result = 4 / %var</i>
1002 <!-- _______________________________________________________________________ -->
1003 </ul><a name="i_rem"><h4><hr size=0>'<tt>rem</tt>' Instruction</h4><ul>
1007 <result> = rem <ty> <var1>, <var2> <i>; yields {ty}:result</i>
1011 The '<tt>rem</tt>' instruction returns the remainder from the division of its two operands.<p>
1014 The two arguments to the '<tt>rem</tt>' instruction must be either <a href="#t_integer">integer</a> or <a href="#t_floating">floating point</a> values. Both arguments must have identical types.<p>
1018 This returns the <i>remainder</i> of a division (where the result has the same
1019 sign as the divisor), not the <i>modulus</i> (where the result has the same sign
1020 as the dividend) of a value. For more information about the difference, see: <a
1021 href="http://mathforum.org/dr.math/problems/anne.4.28.99.html">The Math
1026 <result> = rem int 4, %var <i>; yields {int}:result = 4 % %var</i>
1030 <!-- _______________________________________________________________________ -->
1031 </ul><a name="i_setcc"><h4><hr size=0>'<tt>set<i>cc</i></tt>' Instructions</h4><ul>
1035 <result> = seteq <ty> <var1>, <var2> <i>; yields {bool}:result</i>
1036 <result> = setne <ty> <var1>, <var2> <i>; yields {bool}:result</i>
1037 <result> = setlt <ty> <var1>, <var2> <i>; yields {bool}:result</i>
1038 <result> = setgt <ty> <var1>, <var2> <i>; yields {bool}:result</i>
1039 <result> = setle <ty> <var1>, <var2> <i>; yields {bool}:result</i>
1040 <result> = setge <ty> <var1>, <var2> <i>; yields {bool}:result</i>
1043 <h5>Overview:</h5> The '<tt>set<i>cc</i></tt>' family of instructions returns a
1044 boolean value based on a comparison of their two operands.<p>
1046 <h5>Arguments:</h5> The two arguments to the '<tt>set<i>cc</i></tt>'
1047 instructions must be of <a href="#t_firstclass">first class</a> or <a
1048 href="#t_pointer">pointer</a> type (it is not possible to compare
1049 '<tt>label</tt>'s, '<tt>array</tt>'s, '<tt>structure</tt>' or '<tt>void</tt>'
1050 values, etc...). Both arguments must have identical types.<p>
1054 The '<tt>seteq</tt>' instruction yields a <tt>true</tt> '<tt>bool</tt>' value if
1055 both operands are equal.<br>
1057 The '<tt>setne</tt>' instruction yields a <tt>true</tt> '<tt>bool</tt>' value if
1058 both operands are unequal.<br>
1060 The '<tt>setlt</tt>' instruction yields a <tt>true</tt> '<tt>bool</tt>' value if
1061 the first operand is less than the second operand.<br>
1063 The '<tt>setgt</tt>' instruction yields a <tt>true</tt> '<tt>bool</tt>' value if
1064 the first operand is greater than the second operand.<br>
1066 The '<tt>setle</tt>' instruction yields a <tt>true</tt> '<tt>bool</tt>' value if
1067 the first operand is less than or equal to the second operand.<br>
1069 The '<tt>setge</tt>' instruction yields a <tt>true</tt> '<tt>bool</tt>' value if
1070 the first operand is greater than or equal to the second operand.<p>
1074 <result> = seteq int 4, 5 <i>; yields {bool}:result = false</i>
1075 <result> = setne float 4, 5 <i>; yields {bool}:result = true</i>
1076 <result> = setlt uint 4, 5 <i>; yields {bool}:result = true</i>
1077 <result> = setgt sbyte 4, 5 <i>; yields {bool}:result = false</i>
1078 <result> = setle sbyte 4, 5 <i>; yields {bool}:result = true</i>
1079 <result> = setge sbyte 4, 5 <i>; yields {bool}:result = false</i>
1084 <!-- ======================================================================= -->
1085 </ul><table width="100%" bgcolor="#441188" border=0 cellpadding=4 cellspacing=0>
1086 <tr><td> </td><td width="100%"> <font color="#EEEEFF" face="Georgia,Palatino"><b>
1087 <a name="bitwiseops">Bitwise Binary Operations
1088 </b></font></td></tr></table><ul>
1090 Bitwise binary operators are used to do various forms of bit-twiddling in a
1091 program. They are generally very efficient instructions, and can commonly be
1092 strength reduced from other instructions. They require two operands, execute an
1093 operation on them, and produce a single value. The resulting value of the
1094 bitwise binary operators is always the same type as its first operand.<p>
1096 <!-- _______________________________________________________________________ -->
1097 </ul><a name="i_and"><h4><hr size=0>'<tt>and</tt>' Instruction</h4><ul>
1101 <result> = and <ty> <var1>, <var2> <i>; yields {ty}:result</i>
1105 The '<tt>and</tt>' instruction returns the bitwise logical and of its two operands.<p>
1109 The two arguments to the '<tt>and</tt>' instruction must be <a
1110 href="#t_integral">integral</a> values. Both arguments must have identical
1116 The truth table used for the '<tt>and</tt>' instruction is:<p>
1118 <center><table border=1 cellspacing=0 cellpadding=4>
1119 <tr><td>In0</td> <td>In1</td> <td>Out</td></tr>
1120 <tr><td>0</td> <td>0</td> <td>0</td></tr>
1121 <tr><td>0</td> <td>1</td> <td>0</td></tr>
1122 <tr><td>1</td> <td>0</td> <td>0</td></tr>
1123 <tr><td>1</td> <td>1</td> <td>1</td></tr>
1124 </table></center><p>
1129 <result> = and int 4, %var <i>; yields {int}:result = 4 & %var</i>
1130 <result> = and int 15, 40 <i>; yields {int}:result = 8</i>
1131 <result> = and int 4, 8 <i>; yields {int}:result = 0</i>
1136 <!-- _______________________________________________________________________ -->
1137 </ul><a name="i_or"><h4><hr size=0>'<tt>or</tt>' Instruction</h4><ul>
1141 <result> = or <ty> <var1>, <var2> <i>; yields {ty}:result</i>
1144 <h5>Overview:</h5> The '<tt>or</tt>' instruction returns the bitwise logical
1145 inclusive or of its two operands.<p>
1149 The two arguments to the '<tt>or</tt>' instruction must be <a
1150 href="#t_integral">integral</a> values. Both arguments must have identical
1156 The truth table used for the '<tt>or</tt>' instruction is:<p>
1158 <center><table border=1 cellspacing=0 cellpadding=4>
1159 <tr><td>In0</td> <td>In1</td> <td>Out</td></tr>
1160 <tr><td>0</td> <td>0</td> <td>0</td></tr>
1161 <tr><td>0</td> <td>1</td> <td>1</td></tr>
1162 <tr><td>1</td> <td>0</td> <td>1</td></tr>
1163 <tr><td>1</td> <td>1</td> <td>1</td></tr>
1164 </table></center><p>
1169 <result> = or int 4, %var <i>; yields {int}:result = 4 | %var</i>
1170 <result> = or int 15, 40 <i>; yields {int}:result = 47</i>
1171 <result> = or int 4, 8 <i>; yields {int}:result = 12</i>
1175 <!-- _______________________________________________________________________ -->
1176 </ul><a name="i_xor"><h4><hr size=0>'<tt>xor</tt>' Instruction</h4><ul>
1180 <result> = xor <ty> <var1>, <var2> <i>; yields {ty}:result</i>
1185 The '<tt>xor</tt>' instruction returns the bitwise logical exclusive or of its
1186 two operands. The <tt>xor</tt> is used to implement the "one's complement"
1187 operation, which is the "~" operator in C.<p>
1191 The two arguments to the '<tt>xor</tt>' instruction must be <a
1192 href="#t_integral">integral</a> values. Both arguments must have identical
1198 The truth table used for the '<tt>xor</tt>' instruction is:<p>
1200 <center><table border=1 cellspacing=0 cellpadding=4>
1201 <tr><td>In0</td> <td>In1</td> <td>Out</td></tr>
1202 <tr><td>0</td> <td>0</td> <td>0</td></tr>
1203 <tr><td>0</td> <td>1</td> <td>1</td></tr>
1204 <tr><td>1</td> <td>0</td> <td>1</td></tr>
1205 <tr><td>1</td> <td>1</td> <td>0</td></tr>
1206 </table></center><p>
1211 <result> = xor int 4, %var <i>; yields {int}:result = 4 ^ %var</i>
1212 <result> = xor int 15, 40 <i>; yields {int}:result = 39</i>
1213 <result> = xor int 4, 8 <i>; yields {int}:result = 12</i>
1214 <result> = xor int %V, -1 <i>; yields {int}:result = ~%V</i>
1218 <!-- _______________________________________________________________________ -->
1219 </ul><a name="i_shl"><h4><hr size=0>'<tt>shl</tt>' Instruction</h4><ul>
1223 <result> = shl <ty> <var1>, ubyte <var2> <i>; yields {ty}:result</i>
1228 The '<tt>shl</tt>' instruction returns the first operand shifted to the left a
1229 specified number of bits.
1233 The first argument to the '<tt>shl</tt>' instruction must be an <a
1234 href="#t_integer">integer</a> type. The second argument must be an
1235 '<tt>ubyte</tt>' type.<p>
1239 The value produced is <tt>var1</tt> * 2<sup><tt>var2</tt></sup>.<p>
1244 <result> = shl int 4, ubyte %var <i>; yields {int}:result = 4 << %var</i>
1245 <result> = shl int 4, ubyte 2 <i>; yields {int}:result = 16</i>
1246 <result> = shl int 1, ubyte 10 <i>; yields {int}:result = 1024</i>
1250 <!-- _______________________________________________________________________ -->
1251 </ul><a name="i_shr"><h4><hr size=0>'<tt>shr</tt>' Instruction</h4><ul>
1256 <result> = shr <ty> <var1>, ubyte <var2> <i>; yields {ty}:result</i>
1260 The '<tt>shr</tt>' instruction returns the first operand shifted to the right a specified number of bits.
1263 The first argument to the '<tt>shr</tt>' instruction must be an <a href="#t_integer">integer</a> type. The second argument must be an '<tt>ubyte</tt>' type.<p>
1267 If the first argument is a <a href="#t_signed">signed</a> type, the most
1268 significant bit is duplicated in the newly free'd bit positions. If the first
1269 argument is unsigned, zero bits shall fill the empty positions.<p>
1273 <result> = shr int 4, ubyte %var <i>; yields {int}:result = 4 >> %var</i>
1274 <result> = shr uint 4, ubyte 1 <i>; yields {uint}:result = 2</i>
1275 <result> = shr int 4, ubyte 2 <i>; yields {int}:result = 1</i>
1276 <result> = shr sbyte 4, ubyte 3 <i>; yields {sbyte}:result = 0</i>
1277 <result> = shr sbyte -2, ubyte 1 <i>; yields {sbyte}:result = -1</i>
1284 <!-- ======================================================================= -->
1285 </ul><table width="100%" bgcolor="#441188" border=0 cellpadding=4 cellspacing=0>
1286 <tr><td> </td><td width="100%"> <font color="#EEEEFF" face="Georgia,Palatino"><b>
1287 <a name="memoryops">Memory Access Operations
1288 </b></font></td></tr></table><ul>
1290 A key design point of an SSA-based representation is how it represents memory.
1291 In LLVM, no memory locations are in SSA form, which makes things very simple.
1292 This section describes how to read, write, allocate and free memory in LLVM.<p>
1295 <!-- _______________________________________________________________________ -->
1296 </ul><a name="i_malloc"><h4><hr size=0>'<tt>malloc</tt>' Instruction</h4><ul>
1300 <result> = malloc <type>, uint <NumElements> <i>; yields {type*}:result</i>
1301 <result> = malloc <type> <i>; yields {type*}:result</i>
1305 The '<tt>malloc</tt>' instruction allocates memory from the system heap and returns a pointer to it.<p>
1309 The the '<tt>malloc</tt>' instruction allocates
1310 <tt>sizeof(<type>)*NumElements</tt> bytes of memory from the operating
1311 system, and returns a pointer of the appropriate type to the program. The
1312 second form of the instruction is a shorter version of the first instruction
1313 that defaults to allocating one element.<p>
1315 '<tt>type</tt>' must be a sized type.<p>
1319 Memory is allocated using the system "<tt>malloc</tt>" function, and a pointer
1324 %array = malloc [4 x ubyte ] <i>; yields {[%4 x ubyte]*}:array</i>
1326 %size = <a href="#i_add">add</a> uint 2, 2 <i>; yields {uint}:size = uint 4</i>
1327 %array1 = malloc ubyte, uint 4 <i>; yields {ubyte*}:array1</i>
1328 %array2 = malloc [12 x ubyte], uint %size <i>; yields {[12 x ubyte]*}:array2</i>
1332 <!-- _______________________________________________________________________ -->
1333 </ul><a name="i_free"><h4><hr size=0>'<tt>free</tt>' Instruction</h4><ul>
1337 free <type> <value> <i>; yields {void}</i>
1342 The '<tt>free</tt>' instruction returns memory back to the unused memory heap, to be reallocated in the future.<p>
1347 '<tt>value</tt>' shall be a pointer value that points to a value that was
1348 allocated with the '<tt><a href="#i_malloc">malloc</a></tt>' instruction.<p>
1353 Access to the memory pointed to by the pointer is not longer defined after this instruction executes.<p>
1357 %array = <a href="#i_malloc">malloc</a> [4 x ubyte] <i>; yields {[4 x ubyte]*}:array</i>
1358 free [4 x ubyte]* %array
1362 <!-- _______________________________________________________________________ -->
1363 </ul><a name="i_alloca"><h4><hr size=0>'<tt>alloca</tt>' Instruction</h4><ul>
1367 <result> = alloca <type>, uint <NumElements> <i>; yields {type*}:result</i>
1368 <result> = alloca <type> <i>; yields {type*}:result</i>
1373 The '<tt>alloca</tt>' instruction allocates memory on the current stack frame of
1374 the procedure that is live until the current function returns to its caller.<p>
1378 The the '<tt>alloca</tt>' instruction allocates
1379 <tt>sizeof(<type>)*NumElements</tt> bytes of memory on the runtime stack,
1380 returning a pointer of the appropriate type to the program. The second form of
1381 the instruction is a shorter version of the first that defaults to allocating
1384 '<tt>type</tt>' may be any sized type.<p>
1388 Memory is allocated, a pointer is returned. '<tt>alloca</tt>'d memory is
1389 automatically released when the function returns. The '<tt>alloca</tt>'
1390 instruction is commonly used to represent automatic variables that must have an
1391 address available. When the function returns (either with the <tt><a
1392 href="#i_ret">ret</a></tt> or <tt><a href="#i_invoke">invoke</a></tt>
1393 instructions), the memory is reclaimed.<p>
1397 %ptr = alloca int <i>; yields {int*}:ptr</i>
1398 %ptr = alloca int, uint 4 <i>; yields {int*}:ptr</i>
1402 <!-- _______________________________________________________________________ -->
1403 </ul><a name="i_load"><h4><hr size=0>'<tt>load</tt>' Instruction</h4><ul>
1407 <result> = load <ty>* <pointer>
1408 <result> = volatile load <ty>* <pointer>
1412 The '<tt>load</tt>' instruction is used to read from memory.<p>
1416 The argument to the '<tt>load</tt>' instruction specifies the memory address to
1417 load from. The pointer must point to a <a href="t_firstclass">first class</a>
1418 type. If the <tt>load</tt> is marked as <tt>volatile</tt> then the optimizer is
1419 not allowed to modify the number or order of execution of this <tt>load</tt>
1420 with other volatile <tt>load</tt> and <tt><a href="#i_store">store</a></tt>
1425 The location of memory pointed to is loaded.
1429 %ptr = <a href="#i_alloca">alloca</a> int <i>; yields {int*}:ptr</i>
1430 <a href="#i_store">store</a> int 3, int* %ptr <i>; yields {void}</i>
1431 %val = load int* %ptr <i>; yields {int}:val = int 3</i>
1437 <!-- _______________________________________________________________________ -->
1438 </ul><a name="i_store"><h4><hr size=0>'<tt>store</tt>' Instruction</h4><ul>
1442 store <ty> <value>, <ty>* <pointer> <i>; yields {void}</i>
1443 volatile store <ty> <value>, <ty>* <pointer> <i>; yields {void}</i>
1447 The '<tt>store</tt>' instruction is used to write to memory.<p>
1451 There are two arguments to the '<tt>store</tt>' instruction: a value to store
1452 and an address to store it into. The type of the '<tt><pointer></tt>'
1453 operand must be a pointer to the type of the '<tt><value></tt>' operand.
1454 If the <tt>store</tt> is marked as <tt>volatile</tt> then the optimizer is not
1455 allowed to modify the number or order of execution of this <tt>store</tt> with
1456 other volatile <tt>load</tt> and <tt><a href="#i_store">store</a></tt>
1459 <h5>Semantics:</h5> The contents of memory are updated to contain
1460 '<tt><value></tt>' at the location specified by the
1461 '<tt><pointer></tt>' operand.<p>
1465 %ptr = <a href="#i_alloca">alloca</a> int <i>; yields {int*}:ptr</i>
1466 <a href="#i_store">store</a> int 3, int* %ptr <i>; yields {void}</i>
1467 %val = load int* %ptr <i>; yields {int}:val = int 3</i>
1473 <!-- _______________________________________________________________________ -->
1474 </ul><a name="i_getelementptr"><h4><hr size=0>'<tt>getelementptr</tt>' Instruction</h4><ul>
1478 <result> = getelementptr <ty>* <ptrval>{, long <aidx>|, ubyte <sidx>}*
1483 The '<tt>getelementptr</tt>' instruction is used to get the address of a
1484 subelement of an aggregate data structure.<p>
1488 This instruction takes a list of <tt>long</tt> values and <tt>ubyte</tt>
1489 constants that indicate what form of addressing to perform. The actual types of
1490 the arguments provided depend on the type of the first pointer argument. The
1491 '<tt>getelementptr</tt>' instruction is used to index down through the type
1492 levels of a structure.<p>
1494 For example, lets consider a C code fragment and how it gets compiled to
1509 int *foo(struct ST *s) {
1510 return &s[1].Z.B[5][13];
1514 The LLVM code generated by the GCC frontend is:
1517 %RT = type { sbyte, [10 x [20 x int]], sbyte }
1518 %ST = type { int, double, %RT }
1520 int* "foo"(%ST* %s) {
1521 %reg = getelementptr %ST* %s, long 1, ubyte 2, ubyte 1, long 5, long 13
1528 The index types specified for the '<tt>getelementptr</tt>' instruction depend on
1529 the pointer type that is being index into. <a href="t_pointer">Pointer</a> and
1530 <a href="t_array">array</a> types require '<tt>long</tt>' values, and <a
1531 href="t_struct">structure</a> types require '<tt>ubyte</tt>'
1532 <b>constants</b>.<p>
1534 In the example above, the first index is indexing into the '<tt>%ST*</tt>' type,
1535 which is a pointer, yielding a '<tt>%ST</tt>' = '<tt>{ int, double, %RT }</tt>'
1536 type, a structure. The second index indexes into the third element of the
1537 structure, yielding a '<tt>%RT</tt>' = '<tt>{ sbyte, [10 x [20 x int]], sbyte
1538 }</tt>' type, another structure. The third index indexes into the second
1539 element of the structure, yielding a '<tt>[10 x [20 x int]]</tt>' type, an
1540 array. The two dimensions of the array are subscripted into, yielding an
1541 '<tt>int</tt>' type. The '<tt>getelementptr</tt>' instruction return a pointer
1542 to this element, thus yielding a '<tt>int*</tt>' type.<p>
1544 Note that it is perfectly legal to index partially through a structure,
1545 returning a pointer to an inner element. Because of this, the LLVM code for the
1546 given testcase is equivalent to:<p>
1549 int* "foo"(%ST* %s) {
1550 %t1 = getelementptr %ST* %s , long 1 <i>; yields %ST*:%t1</i>
1551 %t2 = getelementptr %ST* %t1, long 0, ubyte 2 <i>; yields %RT*:%t2</i>
1552 %t3 = getelementptr %RT* %t2, long 0, ubyte 1 <i>; yields [10 x [20 x int]]*:%t3</i>
1553 %t4 = getelementptr [10 x [20 x int]]* %t3, long 0, long 5 <i>; yields [20 x int]*:%t4</i>
1554 %t5 = getelementptr [20 x int]* %t4, long 0, long 13 <i>; yields int*:%t5</i>
1563 <i>; yields [12 x ubyte]*:aptr</i>
1564 %aptr = getelementptr {int, [12 x ubyte]}* %sptr, long 0, ubyte 1
1569 <!-- ======================================================================= -->
1570 </ul><table width="100%" bgcolor="#441188" border=0 cellpadding=4 cellspacing=0>
1571 <tr><td> </td><td width="100%"> <font color="#EEEEFF" face="Georgia,Palatino"><b>
1572 <a name="otherops">Other Operations
1573 </b></font></td></tr></table><ul>
1575 The instructions in this catagory are the "miscellaneous" instructions, which defy better classification.<p>
1578 <!-- _______________________________________________________________________ -->
1579 </ul><a name="i_phi"><h4><hr size=0>'<tt>phi</tt>' Instruction</h4><ul>
1583 <result> = phi <ty> [ <val0>, <label0>], ...
1588 The '<tt>phi</tt>' instruction is used to implement the φ node in the SSA
1589 graph representing the function.<p>
1593 The type of the incoming values are specified with the first type field. After
1594 this, the '<tt>phi</tt>' instruction takes a list of pairs as arguments, with
1595 one pair for each predecessor basic block of the current block.<p>
1597 There must be no non-phi instructions between the start of a basic block and the
1598 PHI instructions: i.e. PHI instructions must be first in a basic block.<p>
1602 At runtime, the '<tt>phi</tt>' instruction logically takes on the value
1603 specified by the parameter, depending on which basic block we came from in the
1604 last <a href="#terminators">terminator</a> instruction.<p>
1609 Loop: ; Infinite loop that counts from 0 on up...
1610 %indvar = phi uint [ 0, %LoopHeader ], [ %nextindvar, %Loop ]
1611 %nextindvar = add uint %indvar, 1
1616 <!-- _______________________________________________________________________ -->
1617 </ul><a name="i_cast"><h4><hr size=0>'<tt>cast .. to</tt>' Instruction</h4><ul>
1621 <result> = cast <ty> <value> to <ty2> <i>; yields ty2</i>
1626 The '<tt>cast</tt>' instruction is used as the primitive means to convert
1627 integers to floating point, change data type sizes, and break type safety (by
1628 casting pointers).<p>
1632 The '<tt>cast</tt>' instruction takes a value to cast, which must be a first
1633 class value, and a type to cast it to, which must also be a first class type.<p>
1637 This instruction follows the C rules for explicit casts when determining how the
1638 data being cast must change to fit in its new container.<p>
1640 When casting to bool, any value that would be considered true in the context of
1641 a C '<tt>if</tt>' condition is converted to the boolean '<tt>true</tt>' values,
1642 all else are '<tt>false</tt>'.<p>
1644 When extending an integral value from a type of one signness to another (for
1645 example '<tt>sbyte</tt>' to '<tt>ulong</tt>'), the value is sign-extended if the
1646 <b>source</b> value is signed, and zero-extended if the source value is
1647 unsigned. <tt>bool</tt> values are always zero extended into either zero or
1652 %X = cast int 257 to ubyte <i>; yields ubyte:1</i>
1653 %Y = cast int 123 to bool <i>; yields bool:true</i>
1658 <!-- _______________________________________________________________________ -->
1659 </ul><a name="i_call"><h4><hr size=0>'<tt>call</tt>' Instruction</h4><ul>
1663 <result> = call <ty>* <fnptrval>(<param list>)
1668 The '<tt>call</tt>' instruction represents a simple function call.<p>
1672 This instruction requires several arguments:<p>
1675 <li>'<tt>ty</tt>': shall be the signature of the pointer to function value being
1676 invoked. The argument types must match the types implied by this signature.<p>
1678 <li>'<tt>fnptrval</tt>': An LLVM value containing a pointer to a function to be
1679 invoked. In most cases, this is a direct function invocation, but indirect
1680 <tt>call</tt>s are just as possible, calling an arbitrary pointer to function
1683 <li>'<tt>function args</tt>': argument list whose types match the function
1684 signature argument types. If the function signature indicates the function
1685 accepts a variable number of arguments, the extra arguments can be specified.
1690 The '<tt>call</tt>' instruction is used to cause control flow to transfer to a
1691 specified function, with its incoming arguments bound to the specified values.
1692 Upon a '<tt><a href="#i_ret">ret</a></tt>' instruction in the called function,
1693 control flow continues with the instruction after the function call, and the
1694 return value of the function is bound to the result argument. This is a simpler
1695 case of the <a href="#i_invoke">invoke</a> instruction.<p>
1699 %retval = call int %test(int %argc)
1700 call int(sbyte*, ...) *%printf(sbyte* %msg, int 12, sbyte 42);
1704 <!-- _______________________________________________________________________ -->
1705 </ul><a name="i_va_arg"><h4><hr size=0>'<tt>va_arg</tt>' Instruction</h4><ul>
1709 <result> = va_arg <va_list>* <arglist>, <retty>
1714 The '<tt>va_arg</tt>' instruction is used to access arguments passed through the
1715 "variable argument" area of a function call. It corresponds directly to the
1716 <tt>va_arg</tt> macro in C.<p>
1720 This instruction takes a pointer to a <tt>valist</tt> value to read a new
1721 argument from. The return type of the instruction is defined by the second
1722 argument, a type.<p>
1726 The '<tt>va_arg</tt>' instruction works just like the <tt>va_arg</tt> macro
1727 available in C. In a target-dependent way, it reads the argument indicated by
1728 the value the arglist points to, updates the arglist, then returns a value of
1729 the specified type. This instruction should be used in conjunction with the
1730 variable argument handling <a href="#int_varargs">Intrinsic Functions</a>.<p>
1732 It is legal for this instruction to be called in a function which does not take
1733 a variable number of arguments, for example, the <tt>vfprintf</tt> function.<p>
1735 <tt>va_arg</tt> is an LLVM instruction instead of an <a
1736 href="#intrinsics">intrinsic function</a> because the return type depends on an
1741 See the <a href="#int_varargs">variable argument processing</a> section.<p>
1743 <!-- *********************************************************************** -->
1744 </ul><table width="100%" bgcolor="#330077" border=0 cellpadding=4 cellspacing=0>
1745 <tr><td align=center><font color="#EEEEFF" size=+2 face="Georgia,Palatino"><b>
1746 <a name="intrinsics">Intrinsic Functions
1747 </b></font></td></tr></table><ul>
1748 <!-- *********************************************************************** -->
1750 LLVM supports the notion of an "intrinsic function". These functions have well
1751 known names and semantics, and are required to follow certain restrictions.
1752 Overall, these instructions represent an extension mechanism for the LLVM
1753 language that does not require changing all of the transformations in LLVM to
1754 add to the language (or the bytecode reader/writer, the parser, etc...).<p>
1756 Intrinsic function names must all start with an "<tt>llvm.</tt>" prefix, this
1757 prefix is reserved in LLVM for intrinsic names, thus functions may not be named
1758 this. Intrinsic functions must always be external functions: you cannot define
1759 the body of intrinsic functions. Intrinsic functions may only be used in call
1760 or invoke instructions: it is illegal to take the address of an intrinsic
1761 function. Additionally, because intrinsic functions are part of the LLVM
1762 language, it is required that they all be documented here if any are added.<p>
1764 Unless an intrinsic function is target-specific, there must be a lowering pass
1765 to eliminate the intrinsic or all backends must support the intrinsic
1769 <!-- ======================================================================= -->
1770 </ul><table width="100%" bgcolor="#441188" border=0 cellpadding=4 cellspacing=0>
1771 <tr><td> </td><td width="100%"> <font color="#EEEEFF" face="Georgia,Palatino"><b>
1772 <a name="int_varargs">Variable Argument Handling Intrinsics
1773 </b></font></td></tr></table><ul>
1775 Variable argument support is defined in LLVM with the <a
1776 href="#i_va_arg"><tt>va_arg</tt></a> instruction and these three intrinsic
1777 functions. These function correspond almost directly to the similarly named
1778 macros defined in the <tt><stdarg.h></tt> header file.<p>
1780 All of these functions operate on arguments that use a target-specific type
1781 "<tt>va_list</tt>". The LLVM assembly language reference manual does not define
1782 what this type is, so all transformations should be prepared to handle
1783 intrinsics with any type used.<p>
1785 This example shows how the <a href="#i_va_arg"><tt>va_arg</tt></a> instruction
1786 and the variable argument handling intrinsic functions are used.<p>
1789 int %test(int %X, ...) {
1790 ; Allocate two va_list items. On this target, va_list is of type sbyte*
1794 ; Initialize variable argument processing
1795 call void (sbyte**)* %<a href="#i_va_start">llvm.va_start</a>(sbyte** %ap)
1797 ; Read a single integer argument
1798 %tmp = <a href="#i_va_arg">va_arg</a> sbyte** %ap, int
1800 ; Demonstrate usage of llvm.va_copy and llvm_va_end
1801 %apv = load sbyte** %ap
1802 call void %<a href="#i_va_copy">llvm.va_copy</a>(sbyte** %aq, sbyte* %apv)
1803 call void %<a href="#i_va_end">llvm.va_end</a>(sbyte** %aq)
1805 ; Stop processing of arguments.
1806 call void %<a href="#i_va_end">llvm.va_end</a>(sbyte** %ap)
1811 <!-- _______________________________________________________________________ -->
1812 </ul><a name="i_va_start"><h4><hr size=0>'<tt>llvm.va_start</tt>' Intrinsic</h4><ul>
1816 call void (va_list*)* %llvm.va_start(<va_list>* <arglist>)
1821 The '<tt>llvm.va_start</tt>' intrinsic initializes <tt>*<arglist></tt> for
1822 subsequent use by <tt><a href="#i_va_arg">va_arg</a></tt> and <tt><a
1823 href="#i_va_end">llvm.va_end</a></tt>, and must be called before either are
1828 The argument is a pointer to a <tt>va_list</tt> element to initialize.<p>
1832 The '<tt>llvm.va_start</tt>' intrinsic works just like the <tt>va_start</tt>
1833 macro available in C. In a target-dependent way, it initializes the
1834 <tt>va_list</tt> element the argument points to, so that the next call to
1835 <tt>va_arg</tt> will produce the first variable argument passed to the function.
1836 Unlike the C <tt>va_start</tt> macro, this intrinsic does not need to know the
1837 last argument of the function, the compiler can figure that out.<p>
1840 <!-- _______________________________________________________________________ -->
1841 </ul><a name="i_va_end"><h4><hr size=0>'<tt>llvm.va_end</tt>' Intrinsic</h4><ul>
1845 call void (va_list*)* %llvm.va_end(<va_list>* <arglist>)
1850 The '<tt>llvm.va_end</tt>' intrinsic destroys <tt>*<arglist></tt> which
1851 has been initialized previously with <tt><a
1852 href="#i_va_begin">llvm.va_begin</a></tt>.<p>
1856 The argument is a pointer to a <tt>va_list</tt> element to destroy.<p>
1860 The '<tt>llvm.va_end</tt>' intrinsic works just like the <tt>va_end</tt> macro
1861 available in C. In a target-dependent way, it destroys the <tt>va_list</tt>
1862 that the argument points to. Calls to <a
1863 href="#i_va_start"><tt>llvm.va_start</tt></a> and <a
1864 href="#i_va_copy"><tt>llvm.va_copy</tt></a> must be matched exactly with calls
1865 to <tt>llvm.va_end</tt>.<p>
1869 <!-- _______________________________________________________________________ -->
1870 </ul><a name="i_va_copy"><h4><hr size=0>'<tt>llvm.va_copy</tt>' Intrinsic</h4><ul>
1874 call void (va_list*, va_list)* %va_copy(<va_list>* <destarglist>,
1875 <va_list> <srcarglist>)
1880 The '<tt>llvm.va_copy</tt>' intrinsic copies the current argument position from
1881 the source argument list to the destination argument list.<p>
1885 The first argument is a pointer to a <tt>va_list</tt> element to initialize.
1886 The second argument is a <tt>va_list</tt> element to copy from.<p>
1891 The '<tt>llvm.va_copy</tt>' intrinsic works just like the <tt>va_copy</tt> macro
1892 available in C. In a target-dependent way, it copies the source
1893 <tt>va_list</tt> element into the destination list. This intrinsic is necessary
1894 because the <tt><a href="i_va_begin">llvm.va_begin</a></tt> intrinsic may be
1895 arbitrarily complex and require memory allocation, for example.<p>
1898 <!-- *********************************************************************** -->
1900 <!-- *********************************************************************** -->
1905 <address><a href="mailto:sabre@nondot.org">Chris Lattner</a></address>
1906 <!-- Created: Tue Jan 23 15:19:28 CST 2001 -->
1907 <!-- hhmts start -->
1908 Last modified: Mon Sep 8 13:27:14 CDT 2003